Senior Security Engineer

Repay - Realtime Electronic Payments

  • Atlanta, Georgia
  • 7 days ago

    Highlights

    This role sits at the center of our Security Operations Center (SOC) - monitoring and triaging security event queues, conducting proactive threat hunting, and driving incidents from detection through containment and remediation. You will partially own and continuously improve our response playbooks and procedures, build and maintain the automation and integrations that reduce repetitive operational work, operationalize new detections, and assist with vulnerability management as needed.

    Numbers & Facts

    LocationAtlanta, Georgia

    Description

    ABOUT THE ROLE

    REPAY is seeking a highly motivated, self-driven Senior Security Engineer to join our Security Operations team. This role sits at the center of our Security Operations Center (SOC) - monitoring and triaging security event queues, conducting proactive threat hunting, and driving incidents from detection through containment and remediation. You will partially own and continuously improve our response playbooks and procedures, build and maintain the automation and integrations that reduce repetitive operational work, operationalize new detections, and assist with vulnerability management as needed.

    You will also use and train our agentic SOC platform, applying AI-driven workflows to improve triage quality and reduce time to detect and respond. This role participates in the 24/7 weekly on call rotation and partners closely with IT, cloud engineering, network, and application teams to coordinate response actions and remediations. The ideal candidate is a curious, hands-on investigator who is comfortable making decisions under pressure, communicates clearly during active incidents, and turns every incident into a lasting improvement.

    RESPONSIBILITIES

    Security Monitoring and Triage

    • Monitor and triage security event and alert queues across SIEM, EDR/XDR, identity, email, cloud, and network telemetry, ensuring timely and accurate disposition.
    • Investigate alerts to determine scope, impact, and root cause, escalating confirmed incidents according to defined severity criteria.
    • Participate in the 24/7 weekly Security Operations on call rotation, providing timely response to high priority security alerts, incidents, and escalations.
    • Document investigative findings, decisions, and evidence to a standard that supports audit, legal, and post-incident review needs.

    Threat Hunting

    • Conduct proactive, hypothesis-driven threat hunts across endpoint, network, cloud, identity, and SaaS environments.
    • Leverage threat intelligence, MITRE ATT&CK, and adversary tradecraft to surface activity that evades existing detections.
    • Produce hunt reports covering findings, detection gaps, and recommended improvements.

    Incident Response, Playbooks, and Procedures

    • Execute incident response activities including triage, investigation, containment, eradication, and recovery.
    • Own the development, maintenance, and testing of response playbooks, runbooks, and standard operating procedures.
    • Lead or contribute to post-incident reviews, tracking corrective actions to closure and updating playbooks based on lessons learned.
    • Support tabletop exercises and purple team activities to validate detection and response readiness.

    Response Actions Using Security Tooling

    • Take containment and remediation actions using enterprise security tooling, including EDR/XDR host isolation and response, SASE/SSE policy enforcement, secure email gateway (SEG) and DLP rule tuning.
    • Request, review, and implement firewall and network access rule changes to block malicious activity and reduce exposure.

    Agentic SOC Enablement

    • Use the agentic SOC platform in daily operations to accelerate alert triage, enrichment, and investigation.
    • Validate AI-generated conclusions and recommended actions, ensuring appropriate human oversight and governance of automated response.
    • Train, tune, and provide structured feedback on agent workflows, prompts, and knowledge sources to improve accuracy and reduce false positives.

    Security Engineering

    • Design and implement automation for repetitive operational tasks such as enrichment, ticket creation, evidence collection, triaging, and response actions (containment and remediation).
    • Build and maintain automated playbooks and integrations across security and IT platforms using APIs and scripting.
    • Track operational metrics such as time to detect, time to respond, and false positive rate, and use them to prioritize automation work.
    • Update or configure security platforms or infrastructure hosting them using IaC.
    • Operationalize new detections identified through threat hunting.
    • Design and implement security control improvements to address risks and gaps in security monitoring and defense.

    Vulnerability Management Support

    • Assist with vulnerability management activities including scan review, validation, risk-based prioritization, and remediation tracking.
    • Correlate vulnerability data with threat intelligence and evidence of active exploitation to inform remediation urgency.
    • Partner with

    Similar Jobs

    See more jobs